[PATCH] Input: raspberrypi-ts - reject out-of-range point counts and slot IDs

Linkai Gong <[email protected]>
Newsgroups org.kernel.vger.linux-input,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
rpi_ts_poll() copies a firmware snapshot and walks regs.point[] using
num_points. The array has RPI_TS_MAX_SUPPORTED_POINTS entries, and the
GPU is documented to report 0-10 points (99 invalidates the copy).

A corrupted count would index past that snapshot. Slot IDs are a 4-bit
field (0-15) while only 10 MT slots are allocated. Drop the whole frame
instead of clamping, so a bad report cannot update a subset of contacts.

Fixes: 0b9f28fed3f7 ("Input: add official Raspberry Pi's touchscreen driver")
Cc: [email protected]
Signed-off-by: Linkai Gong <[email protected]>
---
 drivers/input/touchscreen/raspberrypi-ts.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/input/touchscreen/raspberrypi-ts.c b/drivers/input/touchscreen/raspberrypi-ts.c
index 841d39a449b3..bd63d95c094b 100644
--- a/drivers/input/touchscreen/raspberrypi-ts.c
+++ b/drivers/input/touchscreen/raspberrypi-ts.c
@@ -78,6 +78,7 @@ static void rpi_ts_poll(struct input_dev *input)
 		 ts->fw_regs_va + offsetof(struct rpi_ts_regs, num_points));
 
 	if (regs.num_points == RPI_TS_NPOINTS_REG_INVALIDATE ||
+	    regs.num_points > RPI_TS_MAX_SUPPORTED_POINTS ||
 	    (regs.num_points == 0 && ts->known_ids == 0))
 		return;
 
@@ -87,6 +88,9 @@ static void rpi_ts_poll(struct input_dev *input)
 		touchid = (regs.point[i].yh >> 4) & 0xf;
 		event_type = (regs.point[i].xh >> 6) & 0x03;
 
+		if (touchid >= RPI_TS_MAX_SUPPORTED_POINTS)
+			return;
+
 		modified_ids |= BIT(touchid);
 
 		if (event_type == RPI_TS_FTS_TOUCH_DOWN ||
-- 
2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.